Bitcoin Forum
October 04, 2024, 01:21:02 PM *
News: Latest Bitcoin Core release: 27.1 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 [176] 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 ... 258 »
3501  Economy / Gambling / Re: [ANN] Bitcointalk Benefit Raffle - Win a Saphire Radeon HD 7970 - 1 BTC to Enter on: April 07, 2012, 12:15:26 AM
Even if its 1000 BTC - 0% Donation and took me 5 mins to set it up, I am completely in my rights to do this, there are no gimicks or tricks, If you dont agree with the Raffle dont participate, very simple. Two questions:

Grue: Are you familiar with Raffles? This raffle has the best odds of any I have ever seen
No, not really, but i did remember the BFL raffle https://bitcointalk.org/index.php?topic=67937.0 had much better odds.

Also no disrespect but I have to ask, Do you really not have anything better to do than troll my raffle? Wink

Its very simple for 1 Bitcoin you get a good chance to win a very high end graphics card and donate a little something to the forum at the same time. If you think I am doing something wrong go start your own raffle.
No, i was simply pointing out that gigavps' calculation was flawed. i know that 20% of this is going to the forum, but that is dwarfed by the 42% that is given to the operator. mathematically, it's obviously better to simply donate to the forum directly. even from a purely "for fun" perspective, you could gamble at other places that have much lower margins.
3502  Economy / Gambling / Re: [ANN] Bitcointalk Benefit Raffle - Win a Saphire Radeon HD 7970 - 1 BTC to Enter on: April 06, 2012, 08:44:54 PM
I think 300 bitcoins for 100bitcoin prize is too large cut.

Let's do some math.

300 BTC - 20% donation (60 BTC) - cost of prize (112 BTC) == 128 BTC profit (42%)

This does not include his time to make the site, setup bit-pay, deal with this thread, pick a winner, etc. So let's say that's 30 hours.

128BTC / 30 hours of work == 4.267 BTC per hour (~$20 / hr)

If you think it is wrong for someone to make $20/hr in BTC to let forum members have a fun and a chance of winning a pretty cool prize, maybe you should try to do better while taking a smaller cut.
that's assuming that he'll never be able to use his scripts again, which is clearly not true. and 30 hours to setup a site (with bugs) is clearly an overestimate.
3503  Bitcoin / Mining / Re: MINING: Adding up the sellers and holders on: April 05, 2012, 11:27:19 PM
Total BTC generated/day:  0.2
Total BTC sold/day:  0
Total BTC held/day:  0.2
3504  Economy / Services / Re: GPUMAX | The Bitcoin Mining Marketplace on: April 05, 2012, 11:00:24 PM
I would like to make a small feature request if it's not going to cause too much trouble: the ability to delete pools/workers
3505  Bitcoin / Development & Technical Discussion / Re: Bitcoin smartcard Point of Sale terminal on: April 05, 2012, 10:57:45 PM
I imagine the "super" cards will be in the range of $20+.  That's probably fine for elite users and the security-conscious.  It will be competing as a more secure alternative to smart phones.  So it's in a niche market anyways.

For regular smart cards, maybe they could be paired with some type of online service that keeps an eye on merchants and perhaps validates transactions based on buying patterns.  At the very least, it would be nice to receive some type of statement at the end of the month to be able to detect fraud.  Otherwise, with nothing but the blockchain to go by, it would be basically impossible to know whether your grocer has a hacked POS terminal that is ripping you off.

So, just from what we've come up with so far, our universal POS terminal is looking at supporting:

  • Smart phones via QR code / NFC
  • Super cards via contact (/ contactless?)
  • Smart cards via contact
  • Online balance service
  • Online transaction verification service
  • Online "lite client" service?

Then on top of that add interfacing with the merchant's accounting system.  And besides magstripe and contact/contactless credit cards, you're competing with Paypal and Dwolla and that new Canadian Mint thing.  It's likely that none of those will cooperate to share hardware. Sad
the cheapest & easiest to implement would be an android/ios client. nearly everyone has a cell phone, and if you're just signing transactions, you don't even need a data plan. however, this will require some way to transfer the signed transaction back to the POS terminal (maybe camera to scan QR code?), so you're looking at additional costs for the merchant.
3506  Bitcoin / Development & Technical Discussion / Re: Bitcoin smartcard Point of Sale terminal on: April 05, 2012, 01:18:05 AM
and do you realize that my attack simply involves making a second transaction, which for all intents and purposes is identical to a normal transaction? until there's a way to prevent the attack, i don't see any point in discussing merchant adoption of an insecure system.

grue, I understand that your attack has relevance to standard smart cards.  How much relevance, I'm not sure, since those basically require you to trust the POS terminal regardless.

But I want you to look again at the hardware I'm proposing be used, and to think about the process flow:

  • The terminal sends the transaction amount to the smart card.
  • The transaction amount is displayed on the smart card.
  • The user presses the button on the smart card to verify the amount.
  • The smart card creates and signs the transaction.

http://www.nidsecurity.com/products/106-details.jpg

There is no way to create multiple transactions without consent.  There is no way to create transactions with the wrong amount without consent.  No sensitive information is transferred to the terminal.  All transactions are created on the card itself using Bitcoin keys that never leave the card.
I see your point now, thanks for clarifying it. Smiley

3507  Bitcoin / Development & Technical Discussion / Re: Bitcoin smartcard Point of Sale terminal on: April 04, 2012, 03:48:33 PM
grue, do you understand that the entire point of a smart card is that the private key never leaves the card?
and do you realize that my attack simply involves making a second transaction, which for all intents and purposes is identical to a normal transaction? until there's a way to prevent the attack, i don't see any point in discussing merchant adoption of an insecure system.
3508  Bitcoin / Development & Technical Discussion / Re: Bitcoin smartcard Point of Sale terminal on: April 04, 2012, 01:33:35 AM
grue, it's obvious that you want to argue with me about other people's proposals.  So here, watch a video about the hardware I'm suggesting:

http://www.building43.com/videos/2011/02/22/nagraid-creating-the-credit-card-of-the-future/
no, i'm arguing about how secure a smartcard system (in general) can be. it's very hard to keep your keys secure if the terminal that you're using can't be trusted. as long as the interface between the card and the user isn't protected, there will always be a risk of a man-in-the-middle attack. if you have a solution to prevent the attack i mentioned earlier, i will be glad to hear it.

One of these measures is to house your security information on a computer chip within the card as opposed to displaying it on the card. Another is a unique display window that reveals a security code necessary to complete a transaction. Each code can only be used once, so even if your card information were stolen, a thief would be unable to effect a transaction without having physical possession of the card and its security code. This window can also display account information such as your last transaction, your balance, how much you have spent this month, even messages from your bank.
too bad i got both
3509  Other / Meta / Re: Dump of posts on: April 04, 2012, 01:02:36 AM
I was unable to download this from any of the FOUR sites linked.. can someone provide a (private) plain HTTP link or torrent to this? I can mirror it once I have a copy.

the rapidshare mirror works fine for me
3510  Other / Beginners & Help / Re: [Selling] Steam account valued at $1770 [5btc Bounty for Middleman] on: April 04, 2012, 01:00:48 AM
DO NOT TRADE

This is in direct violation of Steam's user agreement, and is furthermore extremely risky. The seller can at any time after the sale reclaim the account by contacting Steam Support with CD-keys or credit card numbers associated with the account.

No reputation as well.

DO NOT TRADE
this
3511  Bitcoin / Development & Technical Discussion / Re: Bitcoin smartcard Point of Sale terminal on: April 04, 2012, 12:32:52 AM
If you can install an overlay between the keys and the actual circuit board, you can easily capture the pin, and launch a replay attack.

Well... can't the card be locked immediately after a purchase (say 30-90 s).
but then the smart card will need an internal power source, which will definitely not fit in a card.

If it does what stops anyone from hacking any VISA card in the world?
visa/mastercard is supposedly secure because POS terminals that can process EMV transactions have to be tamper evident (sealed with sticker), and can't have removable faceplates, which should remove the risk of physical keylogging attacks.

maximum rage
1. get yourself a bitcoin POS terminal
2. open it up, and place a circuit that monitors keypad input (remember, this is inside the unit, so 99.9% of the users won't notice)
3. get yourself an arduino and program it so it can do everything a normal POS terminal can do
4. hook the keylogging circuit to the arduino
5. close the entire unit, and make everything look legit
6. place it in your store
7. wait for a customer to buy something
8. the payment gets processed as usual, but now the merchant can charge the customer again, because the card is still inside, and the pin has been logged.
3512  Bitcoin / Development & Technical Discussion / Re: Bitcoin smartcard Point of Sale terminal on: April 03, 2012, 03:59:14 PM
assuming you can even implement a protocol that doesn't allow the private keys to be leaked

A lot of smartcard apps are poorly designed.  But it isn't black magic or anything.  It's definitely doable.  Look at the satellite TV access cards.  They can be reverse engineered, if you have access to the card itself and a scanning electron microscope.
if you can install an overlay between the keys and the actual circuit board, you can easily capture the pin, and launch a replay attack.

a much better way is to have a portable wallet that "pays" a merchant by transferring a signed tx, which the merchant can verify and broadcast.
3513  Bitcoin / Development & Technical Discussion / Re: Bitcoin smartcard Point of Sale terminal on: April 03, 2012, 02:05:56 AM
assuming you can even implement a protocol that doesn't allow the private keys to be leaked, you'll also need some sort of way to prevent unscrupulous merchants from skimming the card using a tampered terminal.

related vid:
http://www.youtube.com/watch?v=JABJlvrZWbY
3514  Bitcoin / Bitcoin Technical Support / Re: When will Tx DB use the merkle tree pruning? on: April 03, 2012, 01:59:28 AM
I would love to code it myself, but I don't understand Bitcoin's code well enough yet. First I'd like to implement a simple python client so I can really understand all the dirty details, and then maybe I'd be able to do something like that.
there's your problem. the only full bitcoin client (correct me if i'm wrong) is in c++.
3515  Bitcoin / Mining / Re: [105% TESTING] I want your hashing power! "Project #2" on: April 02, 2012, 07:47:26 PM
Quote
Status    Hopping Detected!
is there any actual downsides to this?

i'm just using this as a backup pool for gpumax  Cheesy
3516  Economy / Goods / Re: COMMUNITY VECTORBOOTH - show us your face !! on: April 02, 2012, 02:23:37 AM
i guess this won't be very useful for me Sad (check avatar) but i'll give you a free bump
3517  Bitcoin / Bitcoin Discussion / Re: Reuters: Our girl, Naomi O'Leary, did it. on: April 02, 2012, 02:13:10 AM
APRIL FOOLS?
3518  Economy / Trading Discussion / Re: MtGox SSL certificate security warning on Android on: April 02, 2012, 01:01:58 AM
The main site's certificate is signed by Verisign, but the socket connection for displaying the current price is served with a StartSSL certificate. Likely, the StartSSL root cert isn't trusted on your device.
but it says that the problem cert is issued by verisign
3519  Bitcoin / Bitcoin Discussion / Re: Drugs, weapons, terrorism tips and sickening child porn on: April 01, 2012, 03:15:33 PM
Can't read anything

HTTP Status 503 - 503 Server temporarily busy, please try again in a short while
works fine for me
3520  Alternate cryptocurrencies / Altcoin Discussion / Re: Any GPU Coin with Low Difficulty? on: April 01, 2012, 02:16:07 AM
what you need is a design-my-coin or design-my-block-chain tool;

download, input a few parameters, build, run, & profit.

It's so easy, even a caveman can do it.
or use testnet-in-a-box Tongue
Pages: « 1 ... 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 [176] 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 ... 258 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!